Skip to content

feat(jev): cache, fail over, pin versions, and serve Kev routes on /v1/systemone - #1098

Merged
SantiagoDePolonia merged 3 commits into
mainfrom
feat/systemone-followups
Sep 26, 2026
Merged

SantiagoDePolonia merged 3 commits into
mainfrom
feat/systemone-followups

Conversation

@SantiagoDePolonia

@SantiagoDePolonia SantiagoDePolonia commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Follow-up to #1097. Closes the gaps #1097 left open on /v1/systemone.

User-visible impact

  • Response caching: an identical request is answered from the exact cache (X-Cache: HIT (exact)) and recorded in usage as a cache hit with its token counts. The semantic cache never serves System One, since a similar state is not the same decision.

  • Failover: a failover virtual model moves a request to its next target on an availability error (429/5xx by default), in the target's own System One form. Targets without the API (chat models) are skipped, not called; 4xx client errors do not fail over. Attempts appear in the audit log; usage is recorded under the target that answered; failover answers are not cached.

  • Kev routes: POST /v1/systemone/permute and /v1/systemone/separate are native, with virtual models, guardrails, caching, audit, and usage. They are refused for OpenRouter, which answers only the evaluation route.

  • Pinned versions: TypeSafe lists only its aliases but accepts any versioned ID, so jev-1.13.0 now routes without declaring it or setting CONFIGURED_PROVIDER_MODELS_MODE=merge: when named with its provider (jev/jev-1.13.0), bare with exactly one jev provider, or through a virtual model. This is checked before catalog resolution, which would otherwise refresh the provider's model list on every such request.

  • Misuse on OpenAI routes: a System One model (a jev model or an OpenRouter decision model, directly or through a virtual model) sent to chat, /responses, /v1/messages, or embeddings now gets a 400 pointing at POST /v1/systemone, decided from the catalog. Before, OpenRouter's own error told callers to use its /api/alpha/decisions.

  • Quieter guardrail warning: edits a decision request cannot carry (e.g. a chat system prompt) are reported once per kind at warning level, then at debug level, instead of on every request.

  • Docs: new System One API page under Advanced, listed in the API endpoints index; the Jev / Kev provider page now links there.

Notes

  • Cache-hit usage for untyped JSON bodies (System One) is now read like a live passthrough answer instead of recording zero tokens.
  • The System One path now installs the provider-attempt recorder, so failover attempts reach the audit log.
  • Verified end to end against the real OpenRouter API (a free decision model; Jev itself needs OpenRouter credits), a fake Kev server, and Redis: guardrail redaction, exact-cache hits, Kev-to-OpenRouter failover, Kev routes, pinned versions, misuse rejections, the official TypeSafe Python SDK, and identical answers directly vs. through the gateway.

Summary by CodeRabbit

  • New Features
    • Added the native POST /v1/systemone decision endpoint for supported Jev and OpenRouter models, with provider-specific routing, guardrails, auditing, usage tracking, caching, and failover.
    • Added permutation and separate-evaluation diagnostic endpoints for Jev providers.
    • System One requests now appear as a distinct type in audit logs.
    • Unlisted pinned Jev model versions can now be routed without provider model declarations.
  • Documentation
    • Updated API, provider, and caching documentation with endpoint availability, model routing, diagnostic routes, and caching details.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: a602fd40-5c3b-4779-aea8-7d26a5e32ff6

📥 Commits

Reviewing files that changed from the base of the PR and between f6a573e and 6e84963.

📒 Files selected for processing (11)
  • docs/advanced/api-endpoints.mdx
  • docs/advanced/systemone-api.mdx
  • docs/docs.json
  • docs/features/cache.mdx
  • docs/providers/jev.mdx
  • internal/guardrails/workflow_executor.go
  • internal/plugins/exchange/systemone_request.go
  • internal/plugins/exchange/systemone_request_test.go
  • internal/server/model_validation.go
  • internal/server/systemone_dispatch_test.go
  • internal/server/systemone_handler.go

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 2 remain after this review.


📝 Walkthrough

Walkthrough

The change adds System One permutation and separate-question routes. It updates model resolution and request validation, and adds cached dispatch with provider failover. API documentation, audit classification, guardrail logging, and cached JSON usage extraction also change.

Changes

System One request flow

Layer / File(s) Summary
Define and expose System One routes
internal/core/*, internal/server/http.go, internal/server/systemone_handler.go, cmd/gomodel/docs/docs.go, docs/openapi.json, docs/advanced/*, docs/docs.json, docs/features/cache.mdx, docs/providers/jev.mdx, web/dashboard/src/pages/audit-logs/audit-operations.js, web/dashboard/tests/audit-operations.test.js
Registers and classifies the evaluation, permutation, and separation routes. Documents route contracts and provider availability. Audit-path classification includes both diagnostic routes.
Resolve models and validate requests
internal/providers/router_models.go, internal/providers/registry_normalization_test.go, internal/server/model_validation.go, internal/server/systemone_handler.go, internal/server/systemone_dispatch_test.go, config/config.example.yaml
Adds sorted provider-name lookup and routes eligible unlisted Jev model versions. Checks provider and model compatibility and directs System One-only models to the System One endpoint.
Cache requests and dispatch to providers
internal/gateway/failover.go, internal/gateway/failover_policy_test.go, internal/gateway/failover_test.go, internal/server/systemone_handler.go, internal/server/systemone_dispatch.go, internal/server/systemone_dispatch_test.go, docs/features/cache.mdx, docs/advanced/systemone-api.mdx
Dispatches System One requests through response caching and eligible provider failover. Records attempts and usage, and updates the resolved route when a failover target answers.
Track edits and cached usage
internal/guardrails/workflow_executor.go, internal/plugins/exchange/systemone_request.go, internal/plugins/exchange/systemone_request_test.go, internal/usage/extractor.go, internal/usage/extractor_test.go
Deduplicates descriptions of uncarried edits and limits repeated guardrail warnings. Extracts usage from cached JSON responses.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~45 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant Client
  participant SystemOneHandler
  participant ResponseCache
  participant InferenceOrchestrator
  participant JevProvider
  Client->>SystemOneHandler: Submit System One request
  SystemOneHandler->>ResponseCache: Dispatch with cache context
  alt Exact cache hit
    ResponseCache-->>SystemOneHandler: Replay cached response
  else Cache miss or caching disabled
    ResponseCache->>InferenceOrchestrator: Execute passthrough with failover
    InferenceOrchestrator->>JevProvider: Send request to eligible target
    JevProvider-->>InferenceOrchestrator: Return response or error
    InferenceOrchestrator-->>ResponseCache: Return response and answering selector
    ResponseCache-->>SystemOneHandler: Return dispatch result
  end
  SystemOneHandler-->>Client: Proxy response
Loading

Merge Risk: ⚪ Minimal · up to 6e849

The reviewed System One changes have no identified issue requiring resolution before merge.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 6e849

New routes can send decision requests to multiple providers and replay prior answers. The reviewed paths retain access checks and restrict eligible providers, but the expanded behavior warrants design review.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A caller able to use the System One routes can reach eligible configured providers with decision-request state. Where exact caching is enabled, an identical request can instead receive a stored answer without another provider call.

Trust Boundaries and Controls

  • observed — The new routes inherit global authentication when credentials are configured; System One is not among the authentication skip paths. Effective model authorization and provider-route checks precede forwarding. Deployment settings can disable credential enforcement, so route declarations alone do not guarantee authentication.
  • observed — Exact-cache identity includes path, request body, workflow, and guardrail hash. Cache capture refuses responses marked as using failover; cache hits have a separate usage-recording path.

Resilience and Maintainability Implications

  • observed — Live dispatch releases admission on exit, records attempted providers, removes the forwarded idempotency-key header so changed failover bodies do not reuse it, and attributes a successful failover to the executed route.

Hardening Proposals

  • proposed — Verify in the intended deployment that identical cached requests cannot vary by caller-specific provider policy, and that replayed answers retain the required audit attribution; these are validation targets, not established defects.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 65.85% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 41 functions across 21 files. (5 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly summarizes the primary changes: System One caching, failover, pinned-version routing, and Kev routes.
Description check ✅ Passed The description provides a detailed, relevant summary of the changes, user-visible impact, implementation notes, documentation updates, and verification coverage. It omits the template's explicit "## …
Full details: Docstring Coverage

Explanation

Docstring coverage is 65.85% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 41 functions across 21 files. (5 skipped: 5 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit taps a route anew,
Two Kev paths come hopping through.
Cache keeps answers, neat and bright,
Failover finds a route that’s right.
Logs grow quiet, usage clear,
I nibble docs and cheer!

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Medium risk] Adds System One API endpoints and routing for Jev and Kev providers.

The PR appears safe to merge. No new issue remains.

What we checked:

  • Unrelated utility models stay usable: OpenRouter gives this exact catalog shape only to decision models. Models with text, image, embedding, speech, or transcription output get their own mode instead.
Diagram
sequenceDiagram
    participant Client
    participant Server
    participant Guardrails
    participant Cache
    participant Provider
    Client->>Server: POST /v1/systemone route
    Server->>Server: Resolve model and workflow
    Server->>Server: Check model access and route support
    Server->>Guardrails: Check or edit state
    Guardrails-->>Server: Guarded request
    Server->>Cache: Look up exact request
    alt Exact cache hit
        Cache-->>Server: Cached provider response
        Server-->>Client: Response with X-Cache HIT
    else Cache miss
        Server->>Provider: Send request to primary target
        alt Availability error
            Server->>Server: Skip targets without this route
            Server->>Provider: Send to next eligible target
        end
        Provider-->>Server: Native System One response
        Server->>Server: Record audit and usage
        Server-->>Client: Relay response unchanged
    end
Loading

Reviews (3) · Last reviewed commit: "fix(jev): point OpenAI routes at /v1/sys..."

Comment thread internal/server/systemone_dispatch.go Outdated
Comment thread internal/server/systemone_dispatch.go
Comment thread internal/server/systemone_dispatch.go Outdated
Comment thread internal/server/systemone_handler.go
@greptile-apps

greptile-apps Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

RetriggerTREX TREX

No flows tested, and faced 1 obstacle.

Obstacles faced

  • The gateway was not confirmed running; finish the build and confirm Swagger loads.

To reduce obstacles, configure your TREX environment.

@SantiagoDePolonia
SantiagoDePolonia changed the base branch from feat/kev to main September 26, 2026 18:00
@mintlify

mintlify Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
gomodel 🟢 Ready View Preview Sep 26, 2026, 6:32 PM

💡 Tip: Enable Automations to automatically generate PRs for you.

@codecov-commenter

codecov-commenter commented Sep 26, 2026 •

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

❌ Patch coverage is 81.15942% with 39 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
internal/gateway/failover.go 25.00% 24 Missing ⚠️
internal/server/systemone_dispatch.go 88.46% 9 Missing ⚠️
internal/server/systemone_handler.go 92.98% 4 Missing ⚠️
internal/guardrails/workflow_executor.go 75.00% 1 Missing ⚠️
internal/usage/extractor.go 92.85% 1 Missing ⚠️

📢 Thoughts on this report? Let us know!

@SantiagoDePolonia
SantiagoDePolonia merged commit 667453c into main Sep 26, 2026
21 checks passed

This branch was successfully deployed

1 active deployment
staging - docs — 6e849639 Deployed Sep 26, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants